EP1817668A2

Terminal, method and computer program product for validating a software application

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 14 October 2025, 0.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

23 claims: 3 independent, 20 dependent

  1. 1
    Claims of equivalent WO 2006043143 A2 WHAT IS CLAIMED IS:1. A terminal for validating a software application, the terminal comprising: a processor capable of operating an operating system (OS) platform, and operating at least one software application above the OS platform, the software application being associated with a permission record that includes at least one permission identifying at least one service the software application is authorized to receive from the OS platform, wherein the OS platform is capable of receiving a request, from a software application, for a service of the OS platform, wherein the OS platform is also capable of determining if the software application is authorized to receive the requested service based upon the associated permission record, and capable of providing the requested service to the software application if the software application is authorized.
  2. 2
    A terminal according to Claim 1, wherein the OS platform is capable of receiving a plurality of requests from the software application for at least one service of the OS platform, and wherein the OS platform is capable of determining, for each requested service, if the software application is authorized to receive the requested service based upon the associated permission record.
  3. 3
    A terminal according to Claim 1, wherein the OS platform is further capable of verifying an authenticity of the software application, and installing the software application for operation on the terminal if the authenticity of the software application is verified, wherein the OS platform is capable of verifying the authenticity and installing the software application before receiving a request from the software application for a service of the OS platform.
  4. 4
    A terminal according to Claim 3, wherein the OS platform is capable of verifying the authenticity of the software application based upon a source of the software application, the software application having previously been received from the source.
  5. 5
    A terminal according to Claim 3, wherein the OS platform includes a policy database, and wherein the OS platform is further capable of creating the permission record for the software application if the authenticity of the software application is verified, and storing the permission record in the policy database.
  6. 6
    A terminal according to Claim 1, wherein the OS platform is furtlier capable of initiating loading of the software application, verifying an integrity o;f the software application, and thereafter loading the software application for operation on the terminal if the integrity of the software application is verified, and wherein the OS platform is capable of initiating loading of the software application, verifying the integrity, and loading the software application before receiving a request from the software application for a service of the OS platform.
  7. 7
    A terminal according to Claim 6, wherein the permission record associated with the software application further includes a signature associated with the software application, and wherein the OS platform is capable of verifying the integrity of the software application by generating a verification signature based upon the software application, comparing the verification signature with the signature in the permission record associated with the software application, and thereafter verifying the integrity of the software application based upon the comparison.
  8. 8
    A method of validating a software application, the method comprising:receiving a request from a software application operating above an operating system (OS) platform, wherein receiving a request comprises receiving a request for a service of the OS platform, the software application being associated with a permission record that includes at least one permission identifying at least one service the software application is authorized to receive from the OS platform;determining if the software application is authorized to receive the requested service based upon the associated permission record;and providing the requested service to the software application if the software application is authorized.
  9. 9
    A method according to Claim 8, wherein receiving a request from the software application comprises receiving a plurality of requests from the software application for at least one service of the OS platform, wherein determining if the software application is authorized comprises determining, for each requested service, if the software application is authorized to receive the requested service t>ased upon the associated permission record.
  10. 10
    A method according to Claim 8 further comprising:verifying an authenticity of the software application;and installing the software application for operation on the terminal if the authenticity of the software application is verified, wherein verifying the authenticity and installing the software application occur before receiving a request from the software application for a service of the OS platform.
  11. 11
    A method according to Claim 10, wherein verifying an authenticity comprises verifying an authenticity of the software application based upon a source of the software application, the software application having previously been received from the source.
  12. 12
    A method according to Claim 10 further comprising:creating the permission record for the software application if the authenticity of the software application is verified;and storing the permission record in a policy database included in the OS platform.
  13. 13
    A method according to Claim 8 further comprising:initiating loading of trie software application;verifying an integrity of the software application;and loading the software application for operation on the terminal if the integrity of the software application is verified, wherein initiating loading of the software application, verifying the integrity, and loading the software application occur before receiving a request from the software application for a service of the OS platform.
  14. 14
    A method according to Claim 13, wherein the permission record associated with the software application further includes a signature associated with the software application, and wherein verifying an integrity of the software application comprises:generating a verification signature based upon the software application;comparing the verification signature with the signature in the permission record associated with the software application;and verifying the integrity of the software application based upon, the comparison.
  15. 15
    A method according to Claim 8, wherein receiving a request comprises receiving a request from a software application operating above the OS platform on a mobile terminal.
  16. 16
    A computer program product for validating a software application, wherein the computer program product comprises at least one computer-readable storage medium having computer-readable program code portions stored therein, the computer-readable program code portions comprising:a first executable portion for receiving a request from a software application operating above an operating system (OS) platform, wherein the first executable portion is adapted to receive a request for a service of the OS platform, the software application being associated with a permission record ttαat includes at least one permission identifying at least one service the software application is authorized to receive from the OS platform;a second executable portion for determining if the software application is authorized to receive the requested service based upon the associated permission record;and a third executable portion for providing the requested service to tire software application if the software application is authorized.
  17. 17
    A computer program product according to Claim 16, wherein the first executable portion is adapted to receive a plurality of requests from the software application for at least one service of the OS platform, wherein the second executable portion is adapted to determine, for each requested service, if the software application is authorized to receive the requested service based upon the associated permission record.
  18. 18
    A computer program product according to Claim 16 further comprising:a fourth executable portion for verifying an authenticity of the software application;and a fifth executable portion for installing the software application fox operation on the terminal if the authenticity of the software application is verified, wherein the fourth and fifth executable portions are adapted to verify the authenticity and install the software application, respectively, before the first executable portion receives a request from the software application for a service of the OS platform.
  19. 19
    A computer program product according to Claim 18, wherein the fourth executable portion is adapted to verify the authenticity of the software application based upon a source of the software application, the software application having previously been received from the source.
  20. 20
    A computer program product according to Claim 18 further comprising:a sixth executable portion for creating the permission record for the software application if the authenticity of the software application is verified" and a seventh executable portion for storing the permission record in a policy database included in the OS platform.
  21. 21
    A computer program product according to Claim 16 further comprising:a fourth executable portion for initiating loading of the software application;a fifth executable portion for verifying an integrity of the software application;and a sixth executable portion for loading the software application for operation on the terminal if the integrity of the software application is verified, wherein the fourth, fifth and sixth executable portions are adapted to initiate loading of the software application, verify the integrity, and load the software application, respectively, before the first executable portion receives a request from the software application for a service of the OS platform.
  22. 22
    A computer program product according to Claim 21, wherein " the permission record associated with the software application further includes a signature associated with the software application, and wherein the fifth exec-xitable portion is adapted to verify an integrity of the software application by generating a verification signature based upon the software application, comparing the verification signature with the signature in the permission record associated with the software application, and thereafter verifying the integrity of the software application based upon the comparison.
  23. 23
    A computer program product according to Claim 16, wherein " the first executable portion is adapted to receive a request from a software application operating above the OS platform on a mobile terminal.
Independent claims23